Impact
An authenticated user session that does not require password confirmation for app‑based multi‑factor authentication (MFA) management actions allows an attacker to add or enable MFA, disable it, and regenerate recovery codes without knowing the account password. The vulnerability stems from missing password re‑authentication and is classified as CWE‑306, improper authentication. While the affected functionality is limited to app‑based MFA, the attacker can lock the legitimate user out by disabling MFA and regenerating new recovery codes, potentially disrupting legitimate access. The CVSS score of 5.4 indicates moderate severity.
Affected Systems
The issue exists in the Filament PHP framework for Laravel. Versions 4.0.0 through 4.13.3 and 5.8.3 are vulnerable; the flaw was addressed in releases 4.13.3 and 5.8.3. No other versions are listed as affected.
Risk and Exploitability
The lack of EPSS data and the fact that the vulnerability is not listed in CISA KEV suggest moderate exploit likelihood, but the flaw can be abused by anyone who gains an authenticated session. An attacker who can log in (or hijack a session) can exploit the weakness without revealing the account password, enabling unauthorized manipulation of MFA settings. The impact is confined to the user whose session is hijacked, but the consequences include potential lockout of the user and removal of necessary recovery mechanisms.
OpenCVE Enrichment